Getting Data In

Monitoring folder stops monitoring files

keycoldstorage
Explorer

I suspect that this has something to do with the fact that my log files are being generated by appending to the end of a flat file.

A monitored folder with two flat files that are being written to is not adding to the index. When I add a test line at the top of the file, Splunk catches that on one file (about 80mb), but not the other (about 3mb). However, it still does not index the additions to the tails of the files.

Do I need to configure tailing? I was under the impression that the folder monitor was supposed to index changes in existing logfiles within the monitored folder.

I should add that these files are written to more than once per five seconds generally. Might that have something to do with my problem? I found this piece of information in the troubleshooter:

Splunk keeps only so many files open at a time (default, 32). If you have files that are written to more than once every 5 seconds, this table should be expandedshould be expanded

Additional information: it appears as though this may have to do with buckets? I have 9 overlapping hot buckets, all of which failing to start splunk-optimize. The errors seem to correspond roughly with the last indexed data in the two logs.

arri

0 Karma

keycoldstorage
Explorer

Just in case some other noob like myself is out there and wonders why this sort of thing might happen, check to see if you've got forwarding enabled. I had turned it on to experiment with it, but didn't realize that, despite checking the store a local copy box, the forwarder would no longer index the data. I then proceeded to ignore the receiver, and forget that I had enabled forwarding, and wonder why it wasn't working right when I came back to it after a month.

Anyway, deleted the forwarding configuration, restarted, and all is well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...